Assess organizational alignment with NIST PQC standards, identify cryptographic risk, and build a practical quantum-safe resilience strategy.
The standardization of NIST's PQC algorithms has marked the start of a new era in cybersecurity defined by immediate and decisive action. With government policies setting clear and aggressive PQC transition timelines, organizations now have a strategic blueprint to modernize their security architecture. Treating these policies as a leading indicator is the most effective way to protect your data and maintain a competitive edge. The time to transition your defenses and secure your data is now.
While formal policy deadlines may seem years away, the primary risk to your data is happening right now. Bad actors are actively executing "Harvest Now, Decrypt Later" strategies by intercepting and archiving encrypted enterprise data today to decrypt it the moment a quantum computer arrives, which could be as soon as 2029.
Transitioning to PQC is an enterprise-wide requirement that represents a significant organizational disruption requiring years to navigate. Success requires recognizing the scale of the challenge and taking decisive action today. Because a thorough migration requires extensive planning, mapping your cryptographic dependencies now is the only way to ensure your environment is ready before legacy standards are phased out.
The Regulatory Backdrop: Accelerating Timelines and Increased Government Emphasis
Palo Alto Networks applauds the recently released Executive Order on Securing the Nation Against Advanced Cryptographic Attacks. Encouragingly, this policy development did not occur in a vacuum. Rather, it’s part of a global trend of government leaders in the United States, Europe, Asia Pacific and beyond sending an unmistakable message – post-quantum readiness is not a tomorrow problem. Dedicated and sustained attention towards PQC migration must begin today.
While the applicable remits of the policy regimes outlined below naturally have some variance, for example, some applying only to government systems while others also including private sector entities the overarching signal should be clear:
Regardless of whether you are covered by one of these regulations, or not, don’t get caught flat-footed as this global policy trend accelerates. Start your PQC migration now.
Global Trends in Post-Quantum Timelines
| Policy Doctrine | Target Jurisdiction | Key Migration Deadlines |
|---|---|---|
| US Executive Order 14412
(Securing the Nation Against Advanced Cryptographic Attacks) |
US Federal Agencies & Covered Government Contractors | October 2026: Agencies must submit their PQC Migration Plan Dec. 31, 2030: Migrate High Value Assets (HVAs) and High Impact Systems (HIS) for key establishment; Targeted deadline for federal contractors to comply with NIST FIPS. Dec. 31, 2031: Migrate HVAs and HIS for digital signatures. |
| EU Coordinated Roadmap on PQC
(Aligned with NIS2 Directive) |
Guidance to EU Member States for harmonized PQC transition, with supplemental guidance to critical sectors | Dec. 31, 2026: Establish national PQC transition roadmaps. Dec. 31, 2030: High-risk use cases transitioned to PQC-by-default. Dec. 31, 2035: Complete full transition to quantum-safe systems. |
| EU Digital Operational Resilience Act (DORA) | European Financial Services Sector (Banks, Insurance, FinTech) | Immediate / Active Requirement: Mandates continuous cryptographic discovery, active inventory mapping, and agile lifecycle management to maintain state-of-the-art security. |
| Australian Signals Directorate (ASD) Guidance | Australian Government, Defense, & Critical Infrastructure | End of 2026: Develop a refined, actionable PQC transition plan. End of 2028: Begin active migration of critical systems and high-priority data. 2030–2035: Phased retirement of legacy asymmetric cryptography. |
| Quantum-Safe Ecosystem in India Roadmap (Ministry of Science & Technology/National Quantum Mission) | Phase 1: Critical Information Infrastructure (CII: Government, Defense, Power, Telecom, Transportation, BFSI) Phase 2: General enterprises |
Dec. 31, 2027: CII sectors to complete risk assessments, CBOM inventories, and pilots. Dec. 31, 2028: CII sectors to complete high-priority system migration (hybrid PKI); General enterprises to establish inventories and governance. Dec. 31, 2029: CII sectors to achieve full PQC transition and quantum resiliency across all CII. Dec. 31, 2030: General enterprises to complete high-priority system migration. Dec. 31, 2033: Achieve enterprise-wide transition across all non-CII entities. |
| Singapore Quantum-Safe Migration Handbook & Quantum Readiness Index (QRI) (Joint Guidance by CSA, GovTech, and IMDA) |
Phase 1: Critical Information Infrastructure (CII) Owners, Government Agencies Phase 2: General Enterprises |
Immediate (2026): CII executive actions (QRI baseline assessment, governance, & "crown jewel" CBOM inventories); General enterprise QRI self-assessment & board-level risk visibility. End of 2028: CII complete dependency mapping, enforce PQC procurement rules, launch hybrid PQC pilots; 2029–2030: Complete full PQC migration for high-risk CII and long-life data systems. End of 2030: General enterprises to enforce crypto-agility in vendor renewals & migrate high-priority apps. By 2035: General enterprises to complete phased retirement of legacy asymmetric cryptography. |
| France (ANSSI) Certification Timeline | Regulated Entities & Security Product Vendors | 2027: Certification gate, ANSSI stops certifying security products lacking hybrid PQC support. 2030: Target deadline for full, standalone quantum-resistant architectures. |
| Japan Interim Report on PQC Migration (Nov. 2025) |
Government Agencies & Related entities, Critical Infrastructure (CI) Operators, and Private Sector | Within FY2026: Formulate engineering roadmap for PQC migration. FY2027 onwards: Ministries will establish guidelines to support private sector transition. By 2035: Complete PQC migration of government agencies. |
| National Advisory Frameworks (Germany’s BSI, UK’s NCSC, Netherlands’ NCSC-NL, Czech Republic NÚKIB) |
General Enterprises and Infrastructure Operators (regional) | Germany (BSI): Targeted migration for CI by 2030. UK (NCSC): Full discovery by 2028; complete adoption by 2035. NL & Czech Republic: Focus on immediate risk audits and hybrid piloting. |
Beyond these national-level frameworks, we’ve also seen sector-specific guidance highlight the urgency of thoughtful PQC migration. For example, recent European Central Bank Banking Supervision guidance appropriately reinforces that PQC adoption, “...must start now and necessitates sustained, strategic investment over time.”
When further dissecting these policies, an overarching consistency in the sequencing recommended for an orderly, but efficient, PQC migration becomes apparent. Organizations are encouraged to first require a continuous, active cryptographic inventory, then document a clear PQC migration pathway, and subsequently remediate identified cryptographic risk.
Organizations are increasingly advised to adopt hybrid cryptographic models, combining proven classical algorithms with newly standardized post-quantum schemes. To bridge the gap between awareness and operational readiness, organizations must move beyond simple compliance and build a repeatable model for cryptographic change.
Palo Alto Networks finds it most helpful to approach this transition using a Discover, Protect, Accelerate framework.
Here is your step-by-step guide on how to evaluate your current risk, build a transition roadmap, and start implementing quantum-safe security today.
Discover: Seeing the Unseen
Readiness starts with visibility. You cannot secure what you cannot see, nor can you migrate algorithms you do not know you are using. The discovery phase focuses on establishing a baseline view of your exposure.
- Inventory Cryptographic Dependencies: Identify the systems and protocols within your environment that handle high-value traffic but lack quantum-resistant handshakes.
- Ask yourself: Which systems represent the greatest "harvest now" risk based on their current reliance on legacy public-key standards
- Map Cryptographic Usage: Start building a cryptographic inventory that maps where quantum-vulnerable algorithms (like RSA, ECC, and Diffie-Hellman) are active.
- Audit Priority Systems: Focus initial discovery on the most critical attack surfaces:
- Internet-facing applications,
- VPNs,
- TLS/mTLS traffic,
- APIs,
- identity systems,
- code-signing environments.
Protect: Securing the Vulnerable
Discovery is useless without accountability and mitigation. The protect phase shifts the focus from finding vulnerabilities to assigning responsibility and mitigating third-party risks.
- Risk Prioritization: Not all cryptographic dependencies carry the same risk.
- Categorize your systems into "do first," "monitor," or "defer" based on the combined impact of data longevity, operational importance, and compliance exposure.
- Assign Clear Ownership: Clearly define the business and technical owners for every critical cryptographic dependency.
- Ensure specific individuals or teams are strictly accountable for the upgrade path of each system.
- Engage Critical Vendors: A significant portion of your risk sits inside third-party tools, SaaS platforms, and cloud infrastructure.
- Do not wait for vendors to reach out. Proactively request their PQC roadmaps, hybrid support plans, and upgrade requirements to ensure your supply chain is resilient.
Accelerate: The Transition
Meeting impending deadlines means enterprises must move immediately from planning to execution. The accelerate phase is about driving momentum, establishing crypto-agility, and leveraging compliance for commercial advantage.
Execute a 30-Day Plan: Spend the first 30 days moving from a "static list" to an "active project":
- Deploy Inline Cipher Translation: Immediately protect legacy applications and unpatchable IoT devices by using firewalls as post-quantum proxies shielding them from "Harvest Now, Decrypt Later" without a code rewrite.
- Automate Hybrid Remediation: Roll out automated certificate rotation and hybrid VPN tunnels to establish a baseline of quantum-resistant communication across your core network.
- Validate Agile Performance: Conduct a high-throughput pilot on a production-adjacent system to measure the "performance tax" of PQC algorithms and optimize hardware resources before full-scale deployment.
Ready to get started?